- Market Insights
- Posts
- The $130M Bug That Was Hiding in Plain Sight
The $130M Bug That Was Hiding in Plain Sight
Bitcoin near $65K, ETF flows turn positive, CLARITY Act hits its final week

Good morning. This is Maestro's Market Insights, where we track the forces shaping Bitcoin and digital capital markets.
Today: institutional Bitcoin capital is diverging, a major hardware wallet flaw is reshaping the conversation around self-custody, and the Bitcoin network is showing one of the rarest mining signals in its history.
P.S. We also launched a new home for Mezzamine. Explore our Bitcoin-native credit markets for miners and lenders at https://www.mezzamine.com/.
Market Prices

Markets: Bitcoin is holding just under $65,000, resistance at $66,000, support near $63,000. Spot ETFs pulled in $626M over three days, the best stretch since May, even as Strategy sold 1,638 BTC to fund buybacks instead of buying more. Mining difficulty sits 14% below January's high, pushing miners like Hut 8 further into AI infrastructure.
Market Updates
CLARITY Act Down to the Wire
Crypto market structure legislation is entering its final window before Congress recesses.
Thune expected to file cloture Thursday, Aug. 7; vote likely this weekend.
White House began negotiating ethics language Aug. 5; a separate stablecoin-yield dispute remains unresolved.
As of Aug. 3, prediction markets priced 2026 passage at just 16%.
Coldcard Hack Grows Past $130M
A 2021 firmware flaw let attackers computationally reconstruct "unguessable" seed phrases, and losses have nearly doubled since disclosure.
1,082.65 BTC (~$70M) drained from 1,196 wallets in 41 minutes on July 30; total losses now exceed $130M.
The bug let key generation fall back to predictable inputs instead of the device's hardware randomness generator.
Coinkite confirmed Mk3 wallets are at risk; Block disputes its claim that newer models are safe.
Capital Flows Split Again
ETFs snapped back hard this week just as the largest corporate Bitcoin holder pulled back.
Spot ETFs pulled in $626M over three days, reversing last week's $33.8M low; IBIT led with $196.83M Wednesday.
Strategy sold 1,638 BTC ($104.7M) to fund STRC dividends and buybacks, pausing new purchases while STRC trades below $100.
Why It Matters
Regulatory clarity, security trust, and institutional behavior are all live right now. A handful of Senate votes could decide market-structure rules for years. One old line of code just cost wallet holders $130M, proof that "cold storage" still depends on trusting a vendor. And institutional demand is split down the middle: ETFs are buying, the biggest corporate holder isn't.
By The Numbers
$626M
US spot Bitcoin ETFs pulled in $626M over the first three trading days of the week, the strongest stretch since early May and a sharp reversal from last week's $33.8M low.
-14%
Bitcoin's mining difficulty sits at 126.23T, 14% below January's peak and 19% below November 2025's all-time high of 155.97T.
$130M+
Losses from the Coldcard hardware wallet hack passed $130M this week as more victims came forward, after a single 2021 firmware flaw exposed predictable seed-phrase generation.
The Deep Dive

The Coldcard Hack Broke More Than Wallets
The Signal
No phishing. No malware. No device ever touched. A single build flag from 2021 sat in production for five years, then let attackers computationally reconstruct "random" seed phrases in 41 minutes. It's being called the worst self-custody failure in Bitcoin's history. That's forcing a question institutional lenders and custodians can't dodge: does holding your own keys actually mean you control your own risk?
The Numbers
Metric | Value |
|---|---|
1,082.65 BTC (~$70M) | |
Wallets drained | 1,196 |
Attack window, wave one | 41 min, July 30, 01:10–01:51 UTC |
$130M+, four attack waves | |
Root cause | 2021 build flag; RNG check verified flag existed, not its value |
Effective key space post-flaw | ~4 billion combos, brute-forceable |
Known attacker groups | 12+, exploiting independently |
July 31, 9:33am ET; MK3, MK4, MK5, Q patched | |
Tested against frontier models; none caught it | |
All crypto hacks, H1 2026 |
What Changed
The flaw: an internal build flag skipped Coldcard's dedicated hardware RNG. A supporting library checked only that the flag existed, not what it was set to, so key generation fell back to predictable inputs (chip serial number, clock registers).
Coinkite initially said only Mk3 was at risk. Independent researchers at Block disputed that, and Coinkite ultimately shipped fixed firmware for MK4, MK5, and Q too. The scope grew after disclosure, not before it.
At least a dozen separate groups exploited the bug independently across four waves, a sign the flaw was easy to rediscover once anyone suspected it.
Coinkite ran the vulnerable code through multiple frontier AI models before the hack. None flagged it: the bug lived at a build/sub-module boundary, not the cryptographic logic AI review tools are tuned to check.
Other major hardware wallets (Ledger, Trezor, Foundation) use different entropy designs: certified secure elements, multiple independent entropy sources, open-source reproducible builds. Researchers see this as an isolated implementation failure, not an industry-wide one.
The Read
Self-custody didn't fail here. One vendor's code did, and that distinction is the whole story. Institutional custody is repositioning around it: the product is no longer "we hold your keys," it's multi-party approval, independent key generation across separate vendors, audit trails, and insurance, because "did you buy a well-reviewed hardware wallet" stopped being sufficient due diligence. The AI angle cuts both ways too: it missed this bug before disclosure, but per Coldcard's NVK, hackers are now running the same tools against every other wallet on the market.
Watch Next
Whether Block's claim of broader Mk4/Q/Mk5 exposure gets independently confirmed at scale, against Coinkite's narrower initial framing.
Early legal theories (breach of warranty, negligence, consumer protection) against Coinkite moving through courts. No findings yet, but the framework is already being built.
Whether AI-assisted vulnerability hunting turns up a flaw in a second hardware wallet before the next disclosure cycle.
Quantum resistance is the long-dated version of this same risk: a vendor-level cryptographic assumption quietly failing years after devices ship. Not an active threat this week, but the same category of blind spot.

Maestro Updates
New Mezzamine Experience Live
The new Mezzamine experience is live, a clearer look at Bitcoin-native credit markets built for miners and lenders.
How Maestro Built Its New Site With AI
Maestro's new site was designed and shipped end-to-end by one person and AI agents, no design or frontend team, from HTML prototypes to subagent-driven development.
Book a Call: Here
Contact Us: [email protected]